Staying Safe Online: Scams, Passwords and 2FA When It Has Already Happened
5 / 5
Finish
When It Has Already Happened ~15min

Move in this order

  1. Change the password, the email account first, then anything sharing that password
  2. Sign out everywhere. Most services have "log out of all devices" in security settings, which kills the attacker's existing session
  3. Enable 2FA if it was not on
  4. Check the recovery settings, attackers add their own recovery email or phone so they can walk back in later. Most people miss this step
  5. Check email rules and forwarding. A hidden forwarding rule is how they keep reading your mail after you lock them out
  6. Tell the people affected, contacts, your bank, your provider

If money moved

Contact the provider immediately (minutes matter) and report to the police or the national cybercrime unit. Keep screenshots of everything; you will need them.

The mistake to avoid

Shame keeps people quiet, and the delay is what makes it worse. Sophisticated, well-resourced people fall for these too. Report early and loudly.

Afterwards

Change reused passwords everywhere, get a password manager, and treat it as the moment your habits improved.

Tasks
Preview